Public secrets exposure leads to supply chain attack on GitHub CodeQL
1–10 of 66 posts
Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL
#2Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL
#3They weren’t kidding on the response time. Very impressive from GitHub.
Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL
#4They weren’t kidding on the response time. Very impressive from GitHub.
Not very impressive to have an exposed public token with full write credentials...
[1] _and failing_.
Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL
#5Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL
#6For their fix, they disabled debug logs...but didn't answer if they changed the temp tokens permissions to something more appropriate for a code analysis engine.
Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL
#7They weren’t kidding on the response time. Very impressive from GitHub.
Not very impressive to have an exposed public token with full write credentials...
Edit: Success is not the absence of vulnerability, but introduction, detection, and response trends.
(Github enterprise comes out of my budget and I am responsible for appsec training and code IR, thoughts and opinions always my own)
Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL
#8Re: Public secrets exposure leads to supply chain attack on GitHub CodeQL
#9Earlier quoted context omitted.
Not very impressive to have an exposed public token with full write credentials...
Trying my best not to break the no snark rule [1], but I'm sure your code is 100% bullet proof against all current and future-yet-invented-attacks. [1] _and failing_.